xenoscr
							
						 
					 | 
					
						
						
							
						
						700d181c7e
					 | 
					
						
						
							
							Adding missing OperatingSystem key in Ilasm.yml
						
						
						
						
						
						
					 | 
					
						2022-09-10 23:30:36 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						d585695b08
					 | 
					
						
						
							
							Adding missing Descriptions.
						
						
						
						
						
						
					 | 
					
						2022-09-10 23:26:10 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						abb1034b00
					 | 
					
						
						
							
							Added missing description to Extexport.yml
						
						
						
						
						
						
					 | 
					
						2022-09-10 23:08:46 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						dd58662ee9
					 | 
					
						
						
							
							Correcting 'UAC bypass' to 'UAC Bypass'
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:58:06 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						0ed1694bf1
					 | 
					
						
						
							
							Correcting 'AWL bypass' to 'AWL Bypass'
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:55:32 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						09e81d0bd1
					 | 
					
						
						
							
							Correcting Cmstp.yml Category value, case.
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:48:08 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						5e0ae9c976
					 | 
					
						
						
							
							Correcting Cmstp.yml Category value.
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:46:13 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								xenoscr
							
						 
					 | 
					
						
						
							
						
						ce36f924fc
					 | 
					
						
						
							
							Removing extra --- from each yaml file
						
						
						
						
						
						
					 | 
					
						2022-09-10 22:16:47 -04:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Ryan Stamp
							
						 
					 | 
					
						
						
							
						
						8810e30f0a
					 | 
					
						
						
							
							Fix incorrect decodehex command syntax (#230)
						
						
						
						
						
						
					 | 
					
						2022-09-02 18:44:23 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						e1df4e9f83
					 | 
					
						
						
							
							Merge remote-tracking branch 'upstream/master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2022-09-02 17:23:45 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Grzegorz Tworek
							
						 
					 | 
					
						
						
							
						
						9b70f38986
					 | 
					
						
						
							
							Create Ldifde.yml
						
						
						
						
						
						
					 | 
					
						2022-08-31 17:58:30 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								721574n
							
						 
					 | 
					
						
						
							
						
						4b564464fd
					 | 
					
						
						
							
							Added external reference for Rundll32
						
						
						
						
						
						
					 | 
					
						2022-08-24 12:11:31 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Oddvar Moe
							
						 
					 | 
					
						
						
							
						
						8283d8d915
					 | 
					
						
						
							
							Delete Dllhost.yml
						
						
						
						
						
						
						
						https://twitter.com/0gtweet/status/1533804788038647808 
						
						
					 | 
					
						2022-06-09 10:51:40 +02:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						539c1da0fa
					 | 
					
						
						
							
							Merge branch 'master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2022-05-25 09:25:42 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Kostas
							
						 
					 | 
					
						
						
							
						
						314f585da9
					 | 
					
						
						
							
							Update Hh.yml
						
						
						
						
						
						
						
						Added SysWoW64 Path 
						
						
					 | 
					
						2022-05-24 15:29:03 -07:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Kostas
							
						 
					 | 
					
						
						
							
						
						aae794c59c
					 | 
					
						
						
							
							Update Hh.yml
						
						
						
						
						
						
						
						Fixing the full path of the hh.exe binary to C:\Windows\hh.exe 
						
						
					 | 
					
						2022-05-24 14:23:18 -07:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						7797a1967c
					 | 
					
						
						
							
							Merge branch 'master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2022-05-24 08:38:50 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						f85eeb748a
					 | 
					
						
						
							
							Add Sigma references to conhost, imewdbld, ie4uinit, ilasm, offlinescannershell and replace (#219)
						
						
						
						
						
						
					 | 
					
						2022-05-23 12:35:58 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Chris "Lopi" Spehn
							
						 
					 | 
					
						
						
							
						
						36945392ca
					 | 
					
						
						
							
							Merge pull request #201 from wietze/new/Conhost
						
						
						
						
						
						
						
						Adding Conhost.exe LOLBAS 
						
						
					 | 
					
						2022-05-19 10:27:10 -06:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								John Dwyer
							
						 
					 | 
					
						
						
							
						
						90b6082f1d
					 | 
					
						
						
							
							Update Rdrleakdiag.yml
						
						
						
						
						
						
					 | 
					
						2022-05-19 13:30:11 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								John Dwyer
							
						 
					 | 
					
						
						
							
						
						e2493d8ccf
					 | 
					
						
						
							
							Detection Resources and Other Updates (LOLBAS-Project#84)
						
						
						
						
						
						
						
						https://github.com/LOLBAS-Project/LOLBAS/issues/84 
						
						
					 | 
					
						2022-05-18 19:00:26 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								John Dwyer
							
						 
					 | 
					
						
						
							
						
						d935f096fd
					 | 
					
						
						
							
							Added rdrleakdiag dump
						
						
						
						
						
						
						
						Added yaml for rdrleakdiag process dumping capability 
						
						
					 | 
					
						2022-05-18 18:58:04 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						d1738b946b
					 | 
					
						
						
							
							Adding various Sigma references (#213)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-05-17 09:18:45 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						79f4cbdb7f
					 | 
					
						
						
							
							Changed tid to T1105 for downloads (#195)
						
						
						
						
						
						
					 | 
					
						2022-05-15 20:38:24 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						b92ee99627
					 | 
					
						
						
							
							Addressing @bohops's feedback
						
						
						
						
						
						
					 | 
					
						2022-05-05 11:12:22 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						5c46dd63f5
					 | 
					
						
						
							
							Giving Hexacorn the proper credit
						
						
						
						
						
						
					 | 
					
						2022-04-07 15:50:39 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						4df2e43c82
					 | 
					
						
						
							
							Adding Conhost.exe LOLBAS
						
						
						
						
						
						
					 | 
					
						2022-04-05 18:46:58 +01:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						55a7ea9a81
					 | 
					
						
						
							
							Fixing wlrmdr entry
						
						
						
						
						
						
					 | 
					
						2022-02-16 21:02:24 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Moshe Kaplan
							
						 
					 | 
					
						
						
							
						
						12c85eb8f0
					 | 
					
						
						
							
							Create wlrmdr.yml (#194)
						
						
						
						
						
						
						
						Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2022-02-16 20:41:14 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						a7f7ec2cc2
					 | 
					
						
						
							
							Changing ATT&CK TID of wuauclt.exe entry (#193)
						
						
						
						
						
						
					 | 
					
						2022-01-23 22:24:59 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						085aaa37b1
					 | 
					
						
						
							
							Adding more missed-out entries
						
						
						
						
						
						
					 | 
					
						2021-12-15 11:50:18 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						52302853c9
					 | 
					
						
						
							
							Merge branch 'master' into windows_11_sprint
						
						
						
						
						
						
					 | 
					
						2021-12-14 17:39:36 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						e51caad3dd
					 | 
					
						
						
							
							Adding Windows 11 reference to missed-out executables
						
						
						
						
						
						
					 | 
					
						2021-12-14 16:57:56 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						6793a7d238
					 | 
					
						
						
							
							Fixing various issues identified
						
						
						
						
						
						
					 | 
					
						2021-12-14 16:50:22 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						adf171d089
					 | 
					
						
						
							
							Applying minor format changes (incorrectly formatted dates, typos, etc.)
						
						
						
						
						
						
					 | 
					
						2021-12-14 15:53:03 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						754a451e76
					 | 
					
						
						
							
							Updating entries that have been confirmed to be working on Windows 11 (21H2)
						
						
						
						
						
						
					 | 
					
						2021-12-14 15:51:43 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						39d4e815af
					 | 
					
						
						
							
							Minor formatting changes (redudant backslashes, incorrect dates, typos, etc.)
						
						
						
						
						
						
					 | 
					
						2021-12-14 14:57:32 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								whickey-r7
							
						 
					 | 
					
						
						
							
						
						18bceb7639
					 | 
					
						
						
							
							Create Unregmp2.yml
						
						
						
						
						
						
						
						Added a new lolbin, unregmp2.exe, used for proxying execution. 
						
						
					 | 
					
						2021-12-06 12:13:24 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						17899acbb0
					 | 
					
						
						
							
							Adding Sigma references to ConfigSecurityPolicy, Diantz, ExtExport & Extrac32 (#184)
						
						
						
						
						
						
					 | 
					
						2021-12-06 11:19:01 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								frack113
							
						 
					 | 
					
						
						
							
						
						2d28767c04
					 | 
					
						
						
							
							Adding new Sigma references (AppInstaller, AspnetCompiler, Bash, Certreq) (#183)
						
						
						
						
						
						
					 | 
					
						2021-11-25 09:42:26 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						f7b30775a4
					 | 
					
						
						
							
							Odbcconf realign to T1218.008, hh.exe to T1218.001
						
						
						
						
						
						
					 | 
					
						2021-11-16 14:09:37 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								bohops
							
						 
					 | 
					
						
						
							
						
						23dd0236ae
					 | 
					
						
						
							
							Detection Resources and Other Updates (#179)
						
						
						
						
						
						
						
						* Add detection links for scripts
* Add detection links for OtherMSBins. Fixed and updated as needed.
* Add detection links for MSBins. Fixed and updated as needed.
* Add detection links for oslibraries
* Updating template for Detections
* Removing empty Detection:Sigma entries
* Remove redundant blank line
* Replacing commit URL with file URL
Co-authored-by: root <root@DESKTOP-5CR935D.localdomain>
Co-authored-by: Wietze <wietze@users.noreply.github.com> 
						
						
					 | 
					
						2021-11-15 08:19:03 -05:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						4860585fb7
					 | 
					
						
						
							
							Adding CustomShellHost.exe LOLBAS
						
						
						
						
						
						
					 | 
					
						2021-11-14 23:26:39 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						2031916b1a
					 | 
					
						
						
							
							ATT&CK realignment, typo fixes (#178)
						
						
						
						
						
						
						
						* Corrected Mitre TID for pnputil
* Fixed Command misspells 
						
						
					 | 
					
						2021-11-14 17:27:17 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						53a4070205
					 | 
					
						
						
							
							Fixed formating
						
						
						
						
						
						
					 | 
					
						2021-11-09 08:16:34 +05:30 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						33a8da933c
					 | 
					
						
						
							
							Added AWL Bypass to Ssh.yml
						
						
						
						
						
						
					 | 
					
						2021-11-09 08:14:43 +05:30 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								akshat pradhan
							
						 
					 | 
					
						
						
							
						
						dfc7d40b1f
					 | 
					
						
						
							
							Create Ssh
						
						
						
						
						
						
					 | 
					
						2021-11-08 22:21:37 +05:30 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						2380c506d4
					 | 
					
						
						
							
							LSASS realign to T1003.001
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:35:58 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						df8c88f4ca
					 | 
					
						
						
							
							Remaping NTDS entries to T1003.003
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:32:44 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 | 
				
			
				
					
						
							
							
								 
								Wietze
							
						 
					 | 
					
						
						
							
						
						bc51cb4e03
					 | 
					
						
						
							
							More changes (mainly changing some T1218 instances to T1202)
						
						
						
						
						
						
					 | 
					
						2021-11-05 20:19:39 +00:00 | 
					
					
						
						
						
							
							
							
							
							
							
							
							
						
					 |